cbcvebase.

Debian Wordpress vulnerabilities

333 known vulnerabilities affecting debian/wordpress.

Total CVEs
333
CISA KEV
0
Public exploits
53
Exploited in wild
13
Severity breakdown
CRITICAL21HIGH56MEDIUM199LOW57

Vulnerabilities

Page 2 of 17
CVE-2016-6896P3HIGHCVSS 7.1PoCfixed in wordpress 4.6.1+dfsg-1 (bookworm)2016
CVE-2016-6896 [HIGH] CVE-2016-6896: wordpress - Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-ad... Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random read operations that deplete the entropy pool.
debian
CVE-2014-9034P3MEDIUMCVSS 5.0PoCfixed in wordpress 4.0.1+dfsg-1 (bookworm)2014
CVE-2014-9034 [MEDIUM] CVE-2014-9034: wordpress - wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.... wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016. Scope: local bookworm: resolved (fixed in 4.0.1+dfsg-1) bullseye: resolved (fixed
debian
CVE-2008-5695P3LOWCVSS 8.5PoCfixed in wordpress 2.3.2 (bookworm)2008
CVE-2008-5695 [HIGH] CVE-2008-5695: wordpress - wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earli... wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins. Scope: local bookworm: resolved
debian
CVE-2019-17671P3MEDIUMCVSS 5.3PoCfixed in wordpress 5.2.4+dfsg1-1 (bookworm)2019
CVE-2019-17671 [MEDIUM] CVE-2019-17671: wordpress - In WordPress before 5.2.4, unauthenticated viewing of certain content is possibl... In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled. Scope: local bookworm: resolved (fixed in 5.2.4+dfsg1-1) bullseye: resolved (fixed in 5.2.4+dfsg1-1) forky: resolved (fixed in 5.2.4+dfsg1-1) sid: resolved (fixed in 5.2.4+dfsg1-1) trixie: resolved (fixed in 5.2.4+dfsg1-1)
debian
CVE-2016-6897P3HIGHCVSS 7.1PoCfixed in wordpress 4.6.1+dfsg-1 (bookworm)2016
CVE-2016-6897 [HIGH] CVE-2016-6897: wordpress - Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin fun... Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896. Scope: local bookworm: r
debian
CVE-2013-0235P3MEDIUMCVSS 6.4PoCfixed in wordpress 3.5.1+dfsg-1 (bookworm)2013
CVE-2013-0235 [MEDIUM] CVE-2013-0235: wordpress - The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP re... The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue. Scope: local bookworm: resolved (fixed in 3.5.1+dfsg-1) bullseye: resolved (fixed in 3.5.1+dfsg-1) forky: resolved (f
debian
CVE-2008-4769P3CRITICALCVSS 9.3PoCfixed in wordpress 2.5.1-1 (bookworm)2008
CVE-2008-4769 [CRITICAL] CVE-2008-4769: wordpress - Directory traversal vulnerability in the get_category_template function in wp-in... Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and earlier, and 2.5, allows remote attackers to include and possibly execute arbitrary PHP files via the cat parameter in index.php. NOTE: some of these details are obtained from third party information. Scope: local bookworm: resolved (fixed in 2
debian
CVE-2006-2667P3MEDIUMCVSS 7.5PoCfixed in wordpress 2.0.3-1 (bookworm)2006
CVE-2006-2667 [HIGH] CVE-2006-2667: wordpress - Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows... Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as dem
debian
CVE-2019-9787P2HIGHCVSS 8.8fixed in wordpress 5.1.1+dfsg1-1 (bookworm)2019
CVE-2019-9787 [HIGH] CVE-2019-9787: wordpress - WordPress before 5.1.1 does not properly filter comment content, leading to Remo... WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary change
debian
CVE-2007-0233P3LOWCVSS 9.3PoCfixed in wordpress 2.1.0-1 (bookworm)2007
CVE-2007-0233 [CRITICAL] CVE-2007-0233: wordpress - wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variable... wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP
debian
CVE-2021-44223P2HIGHCVSS 8.1fixed in wordpress 5.8.1+dfsg1-1 (bookworm)2021
CVE-2021-44223 [HIGH] CVE-2021-44223: wordpress - WordPress before 5.8 lacks support for the Update URI plugin header. This makes ... WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory. Scope: local bookwo
debian
CVE-2007-6318P3LOWCVSS 6.8PoCfixed in wordpress 2.3.2-1 (bookworm)2007
CVE-2007-6318 [MEDIUM] CVE-2007-6318: wordpress - SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earl... SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character. Scope: local bookworm: resolved (fixed in 2.3.2-1) bullseye: resolved (
debian
CVE-2018-20148P2CRITICALCVSS 9.8fixed in wordpress 5.0.1+dfsg1-1 (bookworm)2018
CVE-2018-20148 [CRITICAL] CVE-2018-20148: wordpress - In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP o... In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php. Scope: local bookworm: resolved (fixed in 5.0.1+dfsg1-1) bullseye: r
debian
CVE-2007-2714P3CRITICALCVSS 10.0PoCfixed in wordpress 2.2-1 (bookworm)2007
CVE-2007-2714 [CRITICAL] CVE-2007-2714: wordpress - Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2,... Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors. Scope: local bookworm: resolved (fixed in 2.2-1) bullseye: resolved (fixed in 2.2-1) forky: resolved (fixed in 2.2-1) sid: resolved (fixed in 2.2-1) trixie: resolved (fixed in 2.2-1)
debian
CVE-2009-3890P3LOWCVSS 6.0PoCfixed in wordpress 2.8.6-1 (bookworm)2009
CVE-2009-3890 [MEDIUM] CVE-2009-3890: wordpress - Unrestricted file upload vulnerability in the wp_check_filetype function in wp-i... Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this at
debian
CVE-2017-5487P3MEDIUMCVSS 5.3fixed in wordpress 4.7.1+dfsg-1 (bookworm)2017
CVE-2017-5487 [MEDIUM] CVE-2017-5487: wordpress - wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST AP... wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request. Scope: local bookworm: resolved (fixed in 4.7.1+dfsg-1) bullseye: resolved (fixed in 4.7.
debian
CVE-2005-2108P3HIGHCVSS 7.5PoCfixed in wordpress 1.5.1.3-1 (bookworm)2005
CVE-2005-2108 [HIGH] CVE-2005-2108: wordpress - SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier al... SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file. Scope: local bookworm: resolved (fixed in 1.5.1.3-1) bullseye: resolved (fixed in 1.5.1.3-1) forky: resolved (fixed in 1.5.1.3-
debian
CVE-2007-2821P3HIGHCVSS 7.5PoCfixed in wordpress 2.2-1 (bookworm)2007
CVE-2007-2821 [HIGH] CVE-2007-2821: wordpress - SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 a... SQL injection vulnerability in wp-admin/admin-ajax.php in WordPress before 2.2 allows remote attackers to execute arbitrary SQL commands via the cookie parameter. Scope: local bookworm: resolved (fixed in 2.2-1) bullseye: resolved (fixed in 2.2-1) forky: resolved (fixed in 2.2-1) sid: resolved (fixed in 2.2-1) trixie: resolved (fixed in 2.2-1)
debian
CVE-2023-5561P3MEDIUMCVSS 5.3PoCfixed in wordpress 6.1.6+dfsg1-0+deb12u1 (bookworm)2023
CVE-2023-5561 [MEDIUM] CVE-2023-5561: wordpress - WordPress does not properly restrict which user fields are searchable via the RE... WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack Scope: local bookworm: resolved (fixed in 6.1.6+dfsg1-0+deb12u1) bullseye: resolved (fixed in 5.7.11+dfsg1-0+deb11u1) for
debian
CVE-2007-0107P3MEDIUMCVSS 6.8PoCfixed in wordpress 2.0.6-1 (bookworm)2007
CVE-2007-0107 [MEDIUM] CVE-2007-0107: wordpress - WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate char... WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7. Scope: local bookworm: resolved (fixed in 2.0.6-1) bullseye: resolved (fixed in 2.0.
debian
Debian Wordpress vulnerabilities | cvebase